What officers need to know.
Regulatory shifts, framework updates and operational guidance, curated for Data Protection, IT Security, Compliance and AI Governance leads. Written from the field, verified against primary sources.

AGG Complaints Office 2026: Pricing, Models & Costs
What does an AGG complaints office cost in 2026? Compare internal expenses, standalone software pricing, and external service provider models.

AGG Complaints Office: Internal or External Compared
A complaints office under § 13 AGG is mandatory for every employer. Compare internal and external solutions regarding costs, effort, and liability risks.
Dangerous goods officer exam questions 2021: What has changed and what is important today
Anyone looking for IHK exam questions for the dangerous goods officer in 2021 came across a catalogue that was stable at the time. With the 2023 ADR amendment and the 2025 update, the examination material has shifted. This article classifies the change and shows what a modern order has to achieve today.
ADR 1.1.4.2.1 explains: transport document, multimodality and pre-transport
Section 1.1.4.2.1 ADR regulates the transfer of transport that does not take place exclusively by road. Anyone who prepares containers for the port or drives a truck to the shipping company must know the requirements, otherwise the freight forwarder will block them.
ADR certificate online: What works digitally, what doesn't and who is liable
The ADR certificate cannot be purchased entirely online. This article clarifies which parts of the training are permitted digitally, which IHK examination requires attendance and how you as a company can organise the evidence in an audit-proof manner.
Dangerous goods 30/1863: Transport and document jet fuel in accordance with ADR
Dangerous goods 30/1863 identifies jet fuel as a flammable liquid substance of ADR class 3. We explain the obligations according to ADR 2025, GbV and the CIVAC model for the dangerous goods officer as a service.
Dangerous goods ADR: duties, classes and representatives at a glance
Anyone who ships, transports or loads dangerous goods by road falls under the ADR and the GbV. This article explains classes, exemptions, duties and appointment of the dangerous goods officer, with specific thresholds and audit examples from 2026.
30/1202 Dangerous goods: What the Kemler number means for diesel fuel
The orange warning sign with 30/1202 marks the transport of diesel fuel, gas oil or heating oil, slightly according to ADR. This guide explains the Kemler number, UN number, labelling requirements and the role of the dangerous goods officer.
BSI C5: What the criteria catalogue for cloud compliance requires
The BSI C5 is the German de facto standard for cloud compliance. This article describes the structure, criteria structure, the relationship to ISO/IEC 27001:2022 and how CIVAC halves the mapping effort between ISMS, C5 and client requirements.
Risk analysis with ISO 27001 Annex A: Template, Method and SoA
Risk analysis is the heart of every ISMS according to ISO/IEC 27001:2022. This guide shows what a reliable template looks like, how the 93 controls from Appendix A are integrated and how the Statement of Applicability (SoA) is created.
NIS-2 Implementation Germany: How to Operate the 2026 Deadline as an Officer, Not a Project
The 2026 implementation phase of NIS-2 in Germany shifts the burden from legal interpretation to operational execution. This guide focuses on the officer angle: how to staff, structure, and report a NIS-2 program under Section 38 BSIG without burning out the team.
DORA Regulation: A Practical Guide to the Digital Operational Resilience Act for Financial Entities
Regulation (EU) 2022/2554 (DORA) became applicable on 17 January 2025, binding banks, insurers, investment firms, and critical ICT third parties to five pillars of digital operational resilience. We translate the legal text into operational checklists.
Virtual CISO Services for SaaS Companies in Germany: The Pragmatic Playbook
A pragmatic playbook for SaaS leaders in Germany who need NIS-2 coverage, ISO 27001 readiness and credible answers to enterprise security questionnaires, without hiring a six-figure CISO. Scope, deliverables, pricing and the dual delivery model explained.
External CISO vs. internal CISO: cost comparison, risks and selection criteria
An internal CISO costs 180,000 to 280,000 euros per year including additional costs. External CISO-as-a-Service models range from 36,000 to 180,000 euros, depending on depth. This comparison shows when which variant is worthwhile.
TISAX certification 2026: Scope, test levels and effort realistically planned
TISAX is the German automotive industry’s de-facto requirement for information security in the supply chain. This article explains the scope, assessment levels, test procedure and the clean integration with ISO/IEC 27001:2022.
ISO 27001 certification: process in eight steps from gap analysis to re-audit
The path to ISO 27001:2022 certification can be divided into eight clearly defined steps. We show what is required in the gap analysis, scope, risk assessment, statement of applicability, stage 1 and stage 2 audit and what deadlines you should plan for.
ESG at Heineken: What breweries can learn from the 2026 sustainability report for their own CSRD obligations
Heineken is one of the first European companies to completely prepare their sustainability reporting according to CSRD and ESRS. This article analyses the structure, priorities and lessons learned for medium-sized breweries and beverage manufacturers in the DACH region.
Amundi Global Ecology ESG: Classification and obligations for companies related to ESG
Amundi Global Ecology ESG is an Article 8 SFDR rated equity fund with an ecological focus. This guide classifies the product from a regulatory perspective and shows what obligations ESG-related companies have to make investment decisions and reporting.
Sustainable finance at German banks: SFDR, CSRD and EU taxonomy in interaction
German banks are increasingly demanding reliable ESG data from corporate customers along with their SFDR, CSRD and taxonomy obligations. Anyone who does not systematically collect the required key figures risks a deterioration in financing and conditions. A classification for treasury, ESG and management.
MSCI EMU Climate Change ESG: what the index means for ESG officers
The MSCI EMU Climate Change Index is more than an investment product. It shapes which companies institutional investors with a climate focus still own. Anyone responsible for ESG should understand how the index logic affects their own cost of capital side.
MSCI World ESG or SRI: Differences and implications for corporate compliance
MSCI World ESG and MSCI World SRI are both sustainable index variants, but with significantly different filter strictness. Anyone who knows the methodology understands the expectations of institutional investors and can align their own ESG reporting accordingly.
Deka Future Energy ESG: What companies learn from the fund for their compliance
The Deka Future Energy ESG illustrates which ESG criteria capital market players are examining today. We show what companies learn from the fund logic according to SFDR, EU taxonomy and ESRS and how the compliance platform CIVAC turns them into verifiable reports.
DWS, ESG and the lessons for German companies with ESG obligations
The DWS case has put ESG compliance on the board agenda: greenwashing allegations, regulatory investigations, reputational damage. Anyone who is responsible for ESG today needs risk analysis, documented controls, a reporting line to management and an ESG officer with a clear mandate.
ISO 27001 Implementation Consulting in Berlin: A Buyer's Guide for 2026
Choosing an ISO 27001 implementation consultant in Berlin: scope, deliverables, timelines, costs, and the difference between a consultant who runs the project and one who hands you a templated PDF.